Security access authentication method and device and storage medium

By performing secure access authentication based on the first data packet of the industrial terminal using the user plane network element, the high cost problem caused by the lack of self-authentication of industrial terminals is solved, and secure access with low cost and good human-machine interaction is achieved.

CN121750302APending Publication Date: 2026-03-27CHINA UNITED NETWORK COMM GRP CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-18
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

The lack of self-authentication function in existing industrial terminals leads to high implementation costs for traditional secure access methods, and poor human-computer interaction experience in traditional AI-based terminal interfaces.

Method used

By acquiring the first data packet from the industrial terminal, the user plane network element is used to perform a secure access authentication process to determine the authentication result, without requiring any modification to the industrial terminal.

Benefits of technology

It reduces the implementation cost of secure access to industrial terminals and improves the human-machine interaction experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121750302A_ABST
    Figure CN121750302A_ABST
Patent Text Reader

Abstract

The invention provides a security access authentication method and device and a storage medium, relates to the technical field of communication, and can reduce the implementation cost of security access of an industrial terminal. The method comprises the following steps: receiving a first data message from a first terminal; the first data message comprises an identifier of the first terminal; determining an authentication result of the first terminal based on the first data message; the authentication result of the first terminal is used for indicating whether the first terminal passes security access authentication; and sending an authentication result message to the first terminal, wherein the authentication result message is used for indicating an authentication result of the first terminal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a secure access authentication method, apparatus and storage medium. Background Technology

[0002] With the rapid development of communication technology, industrial private networks are being used more and more widely. Industrial private networks have high requirements for the legitimacy of connected devices; therefore, a reasonable and secure access method for industrial terminals is crucial to ensuring the legitimacy of devices accessing industrial private networks.

[0003] Currently, traditional secure access methods primarily involve receiving authentication requests from user terminals and performing security verification on the user terminals based on these requests. Secure access is achieved only if the verification is successful. However, since existing industrial terminals lack self-authentication capabilities, directly applying traditional secure access methods to them requires modifications, resulting in high implementation costs. Summary of the Invention

[0004] This application provides a secure access authentication method, apparatus, and storage medium, which can reduce the implementation cost of secure access for industrial terminals.

[0005] To achieve the above objectives, this application adopts the following technical solution: In a first aspect, this application provides a secure access authentication method, the method comprising: receiving a first data packet from a first terminal; determining the authentication result of the first terminal based on the first data packet; the authentication result of the first terminal being used to indicate whether the first terminal has passed secure access authentication; and sending an authentication result message to the first terminal, the authentication result message being used to indicate the authentication result of the first terminal.

[0006] The above technical solution brings at least the following beneficial effects: This application obtains the first data packet of the industrial terminal and performs a secure access authentication process for the industrial terminal based on the first data packet, thereby determining the secure access authentication result of the industrial terminal. This process is executed by the user plane network element and does not require modification of the industrial terminal, thus reducing the implementation cost of secure access for the industrial terminal.

[0007] In one possible implementation, the user plane network element includes a user authentication table; the user authentication table includes authentication result information of multiple terminals; the first data packet includes an identifier of a first terminal; based on the first data packet, determining the authentication result of the first terminal includes: determining whether the authentication result information of the first terminal exists in the user authentication table based on the identifier of the first terminal; if the authentication result information of the first terminal does not exist in the user authentication table, determining that the first terminal has not undergone secure access authentication, and executing the secure access procedure of the first terminal based on the first data packet to determine the authentication result of the first terminal; if the authentication result information of the first terminal exists in the user authentication table, determining the authentication result of the first terminal based on the user authentication table.

[0008] In one possible implementation, the first data packet of the first terminal includes the physical address of the first terminal and the directory number of the client front-end device connected to the first terminal. Based on the first data packet, the first terminal performs a secure access authentication process to determine the authentication result of the first terminal, including: determining the secure access authentication request of the first terminal based on the physical address of the first terminal and the directory number of the client front-end device; sending the secure access authentication request to the authentication server; and receiving the authentication result from the authentication server within a preset time period.

[0009] In one possible implementation, the security access authentication request of the first terminal is determined based on the physical address of the first terminal and the directory number of the client's front-end device, including: generating a one-time random number based on a pseudo-random number generation algorithm; encapsulating the current time timestamp, the one-time random number, the directory number, and the physical address to generate a security access authentication request message; and encrypting the request message based on a symmetric encryption algorithm to generate the security access authentication request of the first terminal.

[0010] In one possible implementation, the method further includes: if the authentication result is a first authentication result, updating the authentication status of the first terminal in the authentication status table to the first authentication result information; the first authentication result information is used to indicate that the first terminal has passed secure access authentication; if the authentication result is a second authentication result, updating the authentication status of the first terminal in the authentication status table to the first authentication result information; the second authentication result information is used to indicate that the first terminal has not passed secure access authentication.

[0011] In one possible implementation, the method further includes: forwarding the first data packet and subsequent data packets from the first terminal if the security access authentication result is a first authentication result; and discarding the first data packet and subsequent data packets from the first terminal if the security access authentication result is a second authentication result.

[0012] In one possible implementation, the method further includes: if no secure access authentication result is received from the authentication server within a preset time period, the authentication result is determined as the second authentication result.

[0013] Secondly, this application provides a secure access authentication device, which includes: a communication unit and a processing unit; the communication unit is configured to receive a first data packet from a first terminal; the processing unit is configured to determine the authentication result of the first terminal based on the first data packet; the authentication result of the first terminal is used to indicate whether the first terminal has passed secure access authentication; the communication unit is further configured to send an authentication result message to the first terminal, the authentication result message being used to indicate the authentication result of the first terminal.

[0014] In one possible implementation, the processing unit is specifically configured to: determine whether authentication result information of the first terminal exists in the user authentication table based on the identifier of the first terminal; if the authentication result information of the first terminal does not exist in the user authentication table, determine that the first terminal has not undergone secure access authentication, and execute the secure access procedure of the first terminal based on the first data packet to determine the authentication result of the first terminal; if the authentication result information of the first terminal exists in the user authentication table, determine the authentication result of the first terminal based on the user authentication table.

[0015] In one possible implementation, the processing unit is further configured to determine the secure access authentication request of the first terminal based on the physical address of the first terminal and the directory number of the client's front-end device; the communication unit is further configured to send the secure access authentication request to the authentication server; and the communication unit is further configured to receive the authentication result from the authentication server within a preset time period.

[0016] In one possible implementation, the processing unit is specifically used to: generate a one-time random number based on a pseudo-random number generation algorithm; encapsulate the current time timestamp, the one-time random number, the directory number, and the physical address to generate a secure access authentication request message; and encrypt the request message based on a symmetric encryption algorithm to generate a secure access authentication request for the first terminal.

[0017] In one possible implementation, the processing unit is specifically configured to: update the authentication status of the first terminal in the authentication status table to the first authentication result information when the authentication result is a first authentication result; the first authentication result information is used to indicate that the first terminal has passed the secure access authentication; and update the authentication status of the first terminal in the authentication status table to the first authentication result information when the authentication result is a second authentication result; the second authentication result information is used to indicate that the first terminal has not passed the secure access authentication.

[0018] In one possible implementation, the communication unit is further configured to forward the first data packet and subsequent data packets from the first terminal if the secure access authentication result is a first authentication result; the communication unit is further configured to discard the first data packet and subsequent data packets from the first terminal if the secure access authentication result is a second authentication result.

[0019] In one possible implementation, the processing unit is further configured to determine the authentication result as the second authentication result if no secure access authentication result is received from the authentication server within a preset time period.

[0020] Thirdly, this application provides a secure access authentication device, which includes: a processor and a communication interface; the communication interface and the processor are coupled, and the processor is used to run computer programs or instructions to implement the secure access authentication method as described in the first aspect and any possible implementation of the first aspect.

[0021] Fourthly, this application provides a computer-readable storage medium storing instructions that, when executed on a terminal, cause the terminal to perform the secure access authentication method as described in the first aspect and any possible implementation thereof.

[0022] Fifthly, this application provides a computer program product containing instructions that, when run on a secure access authentication device, cause the secure access authentication device to perform the secure access authentication method as described in the first aspect and any possible implementation thereof.

[0023] In a sixth aspect, this application provides a chip including a processor and a communication interface, the communication interface being coupled to the processor, the processor being used to run computer programs or instructions to implement the secure access authentication method as described in the first aspect and any possible implementation thereof.

[0024] Specifically, the chip provided in this application also includes a memory for storing computer programs or instructions. Attached Figure Description

[0025] Figure 1 This is a schematic diagram of the structure of a secure access authentication system provided in an embodiment of this application; Figure 2 This is a schematic diagram illustrating the composition of a secure access authentication device provided in an embodiment of this application; Figure 3 A flowchart illustrating a secure access authentication method provided in this application embodiment; Figure 4 A schematic diagram of the structure of a user plane network element built-in module provided in an embodiment of this application; Figure 5 A flowchart illustrating secure access authentication of industrial terminals via user plane network elements is provided in this application embodiment. Figure 6 This is a schematic diagram of a secure access authentication device provided in an embodiment of this application. Detailed Implementation

[0026] The secure access authentication method, apparatus, and storage medium provided in the embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0027] In this article, the term "and / or" is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.

[0028] The terms "first" and "second," etc., used in the specification and drawings of this application are used to distinguish different objects or to distinguish different treatments of the same object, rather than to describe a specific order of objects.

[0029] Furthermore, the terms "comprising" and "having," and any variations thereof, used in the description of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus.

[0030] It should be noted that in the embodiments of this application, the words "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0031] In the description of this application, unless otherwise stated, "a plurality of" means two or more.

[0032] With the rapid development of communication technology, industrial private networks are being used more and more widely. Industrial private networks have high requirements for the legitimacy of connected devices; therefore, a reasonable and secure access method for industrial terminals is crucial to ensuring the legitimacy of devices accessing industrial private networks.

[0033] Currently, customer premises equipment (CPE) can authenticate 5G devices accessing 5G private networks through two-factor authentication to ensure device legitimacy. For industrial terminals connected to 5G CPEs, the 5G private network needs to provide an authentication method to prevent service failures caused by unauthorized terminal access. Existing industrial terminals lack their own proactive authentication capabilities, so current industrial private networks do not perform access authentication for them. Traditional secure access solutions require modifications to existing terminals, resulting in significant upgrade costs and hindering widespread adoption.

[0034] Currently, traditional secure access methods primarily involve receiving authentication requests from user terminals and performing security verification on the user terminals based on these requests. Secure access is achieved only if the verification is successful. However, since existing industrial terminals lack self-authentication capabilities, directly applying traditional secure access methods to them requires modifications, resulting in high implementation costs.

[0035] As described above regarding traditional AI-based user interface methods, traditional AI-based terminal interfaces primarily adjust the interface dynamically by learning user behavior and preferences, and interact with users by responding to user clicks. Because traditional AI-based terminal interfaces have cumbersome interaction processes, users often need to complete multiple steps or operations to achieve their goals. Furthermore, traditional AI-based terminal interfaces often provide inaccurate or even erroneous interfaces due to a simplistic understanding of user intent, preventing users from achieving their objectives. Therefore, traditional AI-based terminal interfaces suffer from a poor human-computer interaction experience.

[0036] In view of this, this application proposes a secure access authentication method. This method obtains the first data packet from an industrial terminal and performs a secure access authentication process based on that first data packet to determine the secure access authentication result. This process is executed by user plane network elements and does not require modification of the industrial terminal, thus reducing the implementation cost of secure access for industrial terminals.

[0037] The technical solutions provided in this application can be applied to various communication systems, such as New Radio (NR) communication systems using 5G, future evolution systems, or multiple communication convergence systems.

[0038] For example, Figure 1 This is a schematic diagram of a secure access authentication system provided in an embodiment of this application. The industrial terminal secure access system may include an industrial terminal 101, a CPE device 102, a user plane network element 103, an authentication server 104, and a data network 105. The CPE device 102 can be connected to multiple industrial terminals 101; only one industrial terminal 101 is shown in the figure.

[0039] In one possible implementation, industrial terminal 101 is used to send the first data packet to CPE device 102.

[0040] In one possible implementation, CPE device 102 is used to receive the first data packet from industrial terminal 101 and send the first data packet to user plane network element 103.

[0041] In one possible implementation, user plane network element 103 is used to receive the first data packet from industrial terminal 101. Based on the first data packet, the authentication result of industrial terminal 101 is determined; the authentication result of industrial terminal 101 is used to indicate whether industrial terminal 101 has passed secure access authentication, and an authentication result message is sent to industrial terminal 101, which is used to indicate the authentication result of industrial terminal 101.

[0042] In one possible implementation, the authentication server 104 is used to perform secure access authentication on the industrial terminal 101 and send the authentication result to the user plane network element 103.

[0043] In one possible implementation, data network 105 is used to forward data packets from industrial terminal 101.

[0044] In one possible implementation, the industrial terminal 101 can be: an industrial monitoring terminal for monitoring and managing industrial production processes, such as a monitoring screen or monitoring host installed in a factory workshop to monitor the operating status of equipment and production environment parameters (e.g., temperature, humidity, pressure, etc.) in real time; it also includes an industrial control terminal for industrial automation control, such as a programmable logic controller terminal, which can precisely control industrial equipment according to a preset program; it can also include an industrial data acquisition terminal for industrial data acquisition and transmission, such as acquisition devices specifically designed to collect data from various sensors on the production line; it also includes an industrial maintenance and diagnostic terminal for industrial equipment maintenance and fault diagnosis, such as a dedicated diagnostic instrument capable of fault detection and analysis of large mechanical equipment; and it can also include an industrial logistics terminal for industrial logistics management, such as intelligent terminal devices used for cargo information identification and inventory management in the warehousing and logistics process. This application embodiment does not impose any limitations on this.

[0045] In one possible implementation, the CPE device 102 is a network access and conversion device, which can be a fixed CPE in a broadband scenario or a fixed CPE in a home broadband scenario, such as a 5G CPE. This application embodiment does not impose any limitations on this.

[0046] In one possible implementation, the user plane network element 103 can be a UPF network element responsible for user data processing in the core network, or it can include the part of the session management-related network element that works in conjunction with the UPF and involves user plane policy execution. It can also include customized user plane function components for specific industry applications, such as a user plane module optimized for industrial data transmission in the Industrial Internet. This application embodiment does not limit this.

[0047] In one possible implementation, the authentication server 104 can be a cloud security access authentication server that provides access security authentication, or it can be a security access authentication server dedicated to industrial equipment. This application embodiment does not limit this.

[0048] It should be noted that, Figure 1 This is just an example framework diagram. Figure 1 The number of nodes included and the names of the devices are unlimited, except for... Figure 1 In addition to the functional nodes shown, the secure access authentication system may also include other nodes, such as core network equipment, and this application does not impose any restrictions on this.

[0049] The application scenarios of the embodiments in this application are not limited. The system architecture and business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.

[0050] In practical implementation, Figure 1 All the equipment in the middle can be adopted Figure 2 The shown composition structure, or including Figure 2 The components shown. Figure 2 This is a schematic diagram illustrating the composition of a secure access authentication device 20 provided in an embodiment of this application. The secure access authentication device 20 can be a terminal 101 or a chip or system-on-a-chip within the terminal 101. Alternatively, the secure access authentication device 20 can be an AI smart terminal platform 102 or a chip or system-on-a-chip within the AI ​​smart terminal platform 102. Figure 2 As shown, the secure access authentication device 20 may include a processor 201, a bus 202, a communication interface 203, and a memory 204.

[0051] The processor 201, memory 204 and communication interface 203 can be connected via bus 202.

[0052] The processor 201 can be a central processing unit (CPU), a general-purpose processor, a network processor (NP), a digital signal processor (DSP), a microprocessor, a microcontroller, a programmable logic device (PLD), or any combination thereof. The processor 201 can also be other devices with processing capabilities, such as circuits, devices, or software modules, without limitation.

[0053] Bus 202 is used to transmit information between the components included in the secure access authentication device 20.

[0054] Communication interface 203 is used to communicate with other devices or other communication networks. These other communication networks can be Ethernet, radio access network (RAN), wireless local area networks (WLAN), etc. Communication interface 203 can be a module, circuit, communication interface, or any device capable of enabling communication.

[0055] Memory 204 is used to store instructions. These instructions can be computer programs.

[0056] The memory 204 can be a read-only memory (ROM) or other type of static storage device that can store static information and / or instructions; it can also be a random access memory (RAM) or other type of dynamic storage device that can store information and / or instructions; it can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, etc., without limitation.

[0057] It should be noted that the memory 204 can exist independently of the processor 201 or can be integrated with the processor 201. The memory 204 can be used to store instructions, program code, or some data, etc. The memory 204 can be located inside or outside the secure access authentication device 20, without restriction.

[0058] In one example, processor 201 may include one or more CPUs.

[0059] As an optional implementation, the secure access authentication device 20 includes multiple processors.

[0060] As an optional implementation, the secure access authentication device 20 may also include output devices and input devices. For example, input devices are devices such as keyboards, mice, microphones, or joysticks, and output devices are devices such as displays or speakers.

[0061] It should be noted that the secure access authentication device 20 can be a desktop computer, laptop computer, network server, mobile phone, tablet computer, wireless terminal, embedded device, chip system, or other device. Figure 1 Equipment with a similar structure. Furthermore... Figure 2 The composition shown does not constitute a basis for this. Figure 1 as well as Figure 2 The limitations of each device in the process, except Figure 2 In addition to the components shown, Figure 1 as well as Figure 2 The various devices may include more or fewer components than illustrated, or combine certain components, or have different component arrangements.

[0062] In this embodiment of the application, the chip system may be composed of chips or may include chips and other discrete devices.

[0063] Furthermore, the actions, terms, etc., involved in the various embodiments of this application can be referenced interchangeably without limitation. The message names or parameter names in the messages used for interaction between devices in the embodiments of this application are merely examples, and other names may be used in specific implementations without limitation.

[0064] The following is combined Figure 2 The secure access authentication system shown herein describes the secure access authentication method provided in the embodiments of this application. The actions, terminology, etc., involved in the various embodiments of this application can be referenced interchangeably without limitation. The message names or parameter names in the messages exchanged between various devices in the embodiments of this application are merely examples; other names may be used in specific implementations without limitation. The actions involved in the various embodiments of this application are merely examples; other names may be used in specific implementations. For example, "included in" in the embodiments of this application can be replaced with "carried on" or "carried in," etc.

[0065] In order to solve the problems existing in the prior art, such as Figure 3 As shown in the figure, this application proposes a secure access authentication method that can reduce the implementation cost of secure access for industrial terminals. The method includes: S301, The user plane network element receives the first data packet from the first terminal.

[0066] In one possible implementation, the user plane network element may include a connection manager (CM) module, an operations administration maintenance (OAM) module, a traffic manager (TM) module, and a remote dictionary server (Redis) module.

[0067] In one possible implementation, such as Figure 4The diagram shows a structural schematic of a user plane network element built-in module provided in an embodiment of this application. The CM module interacts with the session management function (SMF) via the session management function and the user plane function N4 interface using Packet Forwarding Control Protocol (PFCP) signaling to implement node management, session management, and other functions, and publishes session information to Redis. The Redis module provides channels for publishing and subscribing to session information and statistics. The OAM module implements configuration management, service registration, system status monitoring, and interface display functions for signaling and statistics. It supports configuring the binding relationship between single network slice selection assistance information (S-NSSAI) and data network name (DNN) and each sub-interface, and supports detailed configuration of the DNN at startup using static configuration. The TM module is used to subscribe to session information and create entries, perform PDR matching for the first data packet of the session, and report statistical information. It manages tens of millions of fast forwarding entries, receives data traffic from various interfaces (such as N3, N6, and N9 interfaces), and performs efficient forwarding according to rules such as forwarding action rule (FAR), buffering action rule (BAR), QoS enforcement rule (QER), and usage reporting rule (URR). It also performs statistics and rate limiting on the data of logical interfaces.

[0068] For example, the TM module may also include the original forwarding module (fwd), flow module, session data module, and report module.

[0069] For example, the CM module may also include an N4 interface module, which can be connected via the Packet Forwarding Control Protocol (PFCP) and SMF, and may also include a parsing module, a high availability (HA) module, and a node sessions module. The parsing module is used to parse the Packet Forwarding Control Protocol.

[0070] For example, the OAM module may include: an interface gateway (Api-gw), a configuration file (Conf), a log (Log), an alarm module (Alarm), a system manager (Sysmgr), a monitoring, control, and data acquisition system (Scada), and a high availability control module (HActrl). The OAM module can connect and interact with external interfaces through the open interface of the interface gateway.

[0071] S302. The user plane network element determines the authentication result of the first terminal based on the first data packet.

[0072] The authentication result of the first terminal is used to indicate whether the first terminal has passed the secure access authentication.

[0073] In one possible implementation, the user plane network element includes a user authentication table, which contains authentication result information for multiple terminals. The first data packet includes an identifier for a first terminal. The process by which the user plane network element determines the authentication result of the first terminal based on the first data packet is as follows: The user plane network element checks whether the authentication result information for the first terminal exists in the user authentication table based on the identifier of the first terminal. If the user plane network element does not have the authentication result information for the first terminal in the user authentication table, it determines that the first terminal has not undergone secure access authentication and executes the secure access procedure for the first terminal based on the first data packet to determine the authentication result of the first terminal. If the user plane network element has the authentication result information for the first terminal in the user authentication table, it determines the authentication result of the first terminal based on the user authentication table.

[0074] For example, the identifier of the first terminal may also include the physical address of the first terminal and the directory number of the client front-end device connected to the first terminal. The user plane network element uses (src Mac, session Id) as keywords to search for the authentication status of the terminal in the authentication status table.

[0075] In one possible implementation, the first data packet of the first terminal includes the physical address of the first terminal and the directory number of the client front-end device connected to the first terminal. Based on the first data packet, the user plane network element executes the secure access authentication process for the first terminal. The process of determining the authentication result of the first terminal is as follows: the user plane network element determines the secure access authentication request of the first terminal based on the physical address of the first terminal and the directory number of the client front-end device. The user plane network element sends the secure access authentication request to the authentication server. The user plane network element receives the authentication result from the authentication server within a preset time period.

[0076] In one possible implementation, the process by which the user plane network element determines the secure access authentication request of the first terminal based on the physical address of the first terminal and the directory number of the client's front-end device is as follows: A one-time random number is generated based on a pseudo-random number generation algorithm. The user plane network element encapsulates the current timestamp, the one-time random number, the directory number, and the physical address to generate a secure access authentication request message. The user plane network element encrypts the request message using a symmetric encryption algorithm to generate the secure access authentication request for the first terminal.

[0077] In one possible implementation, the user plane network element can update the user authentication table based on the authentication result of the authentication server. Specifically, if the authentication result is a first authentication result, the user plane network element updates the authentication status of the first terminal in the authentication status table to the first authentication result information; the first authentication result information indicates that the first terminal has passed secure access authentication. If the authentication result is a second authentication result, the user plane network element updates the authentication status of the first terminal in the authentication status table to the first authentication result information; the second authentication result information indicates that the first terminal has failed secure access authentication.

[0078] In one possible implementation, if the user plane network element does not receive a secure access authentication result from the authentication server within a preset time period, the authentication result will be determined as the second authentication result.

[0079] S303, The user plane network element sends the authentication result message to the first terminal.

[0080] The authentication result message is used to indicate the authentication result of the first terminal.

[0081] In one possible implementation, if the security access authentication result is a first authentication result, the user plane network element forwards the first data packet and subsequent data packets from the first terminal. If the security access authentication result is a second authentication result, the user plane network element discards the first data packet and subsequent data packets from the first terminal.

[0082] In one possible implementation, such as Figure 5The diagram illustrates a flowchart of a secure access authentication process for an industrial terminal via a user plane network element, as provided in this embodiment of the application. The industrial terminal sends its first data packet to a 5G CPE device. The 5G CPE device receives the first data packet and performs secondary encapsulation to generate a Layer 2 data packet, which it then sends to the user plane network element. The TM module of the user plane network element receives the Layer 2 data packet. Based on the Layer 2 data packet, the TM module determines the industrial terminal's physical MAC address and the 5G CPE device's directory MSISDN number, and sends the MAC address and MSISDN number to the GW module in the user plane network element. The GW module in the user plane network element generates an authentication result record indexed by the MAC address and MSISDN number using the MAC address and directory MSISDN number. Based on the MAC address and MSISDN number, the GW module in the user plane network element generates a 3A authentication request and sends it to the corresponding 3A server. Based on the 3A authentication request, the 3A server determines the authentication result of the industrial terminal and sends the authentication result to the GW module in the user plane network element. The GW module sends the authentication result to the TM module. If the GW module does not receive the authentication result within a timeout period, it returns an authentication failure message to the TM module of the UPF. The TM module updates the authentication result of the connected industrial terminal based on the authentication result returned by the GW module. The industrial terminal sends subsequent data packets to the GW module. If the authentication result is successful, the user plane network element forwards all subsequent data packets from that industrial terminal; if the authentication result is unsuccessful, the user plane network element discards all subsequent data packets from that industrial terminal.

[0083] To address the problems existing in the prior art, this application proposes a secure access authentication method. This method acquires multi-source heterogeneous data of terminal users to construct a profile of the target user, and predicts the target user's next action based on the profile and behavioral information. Specifically, by combining the user profile provided in this application with the target user's behavioral information, the method can accurately predict the user's next action, thereby generating a user interface with a high degree of matching to the target user's next action. Furthermore, the user interface generated by this application through the user interface generation model and the predicted next action of the target user has better interaction logic, thus improving the user's human-computer interaction experience.

[0084] It is understood that the aforementioned secure access authentication method can be implemented by a secure access authentication device. To achieve the above functions, the secure access authentication device includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily recognize that, based on the modules and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein, the embodiments disclosed in this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the embodiments disclosed in this application.

[0085] The embodiments disclosed in this application can divide the secure access authentication device generated by the above method examples into functional modules. For example, each function can be divided into its own functional modules, or two or more functions can be integrated into one processing module. The integrated modules can be implemented in hardware or as software functional modules. It should be noted that the module division in the embodiments disclosed in this application is illustrative and only represents one logical functional division; in actual implementation, there may be other division methods.

[0086] Figure 6 This is a schematic diagram of a secure access authentication device provided in an embodiment of this application. Figure 6 As shown, the secure access authentication device 60 can be used to perform... Figure 3 The secure access authentication method shown is illustrated. The secure access authentication device 60 includes a communication unit 601 and a processing unit 602.

[0087] The communication unit 601 is used to receive the first data packet from the first terminal; the processing unit 602 is used to determine the authentication result of the first terminal based on the first data packet; the authentication result of the first terminal is used to indicate whether the first terminal has passed the secure access authentication; the communication unit 601 is also used to send an authentication result message to the first terminal, the authentication result message is used to indicate the authentication result of the first terminal.

[0088] In one possible implementation, the processing unit 602 is specifically configured to: determine whether the authentication result information of the first terminal exists in the user authentication table based on the identifier of the first terminal; if the authentication result information of the first terminal does not exist in the user authentication table, determine that the first terminal has not undergone secure access authentication, and execute the secure access procedure of the first terminal based on the first data packet to determine the authentication result of the first terminal; if the authentication result information of the first terminal exists in the user authentication table, determine the authentication result of the first terminal based on the user authentication table.

[0089] In one possible implementation, the processing unit 602 is further configured to determine the secure access authentication request of the first terminal based on the physical address of the first terminal and the directory number of the client front-end device; the communication unit 601 is further configured to send the secure access authentication request to the authentication server; and the communication unit 601 is further configured to receive the authentication result from the authentication server within a preset time period.

[0090] In one possible implementation, the processing unit 602 is specifically used to: generate a one-time random number based on a pseudo-random number generation algorithm; encapsulate the current time timestamp, the one-time random number, the directory number, and the physical address to generate a secure access authentication request message; and encrypt the request message based on a symmetric encryption algorithm to generate a secure access authentication request for the first terminal.

[0091] In one possible implementation, the processing unit 602 is specifically configured to: update the authentication status of the first terminal in the authentication status table to the first authentication result information when the authentication result is a first authentication result; the first authentication result information is used to indicate that the first terminal has passed the secure access authentication; and update the authentication status of the first terminal in the authentication status table to the first authentication result information when the authentication result is a second authentication result; the second authentication result information is used to indicate that the first terminal has not passed the secure access authentication.

[0092] In one possible implementation, the communication unit 601 is further configured to forward the first data packet and subsequent data packets from the first terminal when the secure access authentication result is the first authentication result; the communication unit 601 is further configured to discard the first data packet and subsequent data packets from the first terminal when the secure access authentication result is the second authentication result.

[0093] In one possible implementation, the processing unit 602 is further configured to determine the authentication result as the second authentication result if no secure access authentication result is received from the authentication server within a preset time period.

[0094] Through the above description of the embodiments, those skilled in the art will clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device, and unit described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0095] This disclosure also provides a computer-readable storage medium storing instructions that, when executed by a processor of an electronic device, enable the electronic device to perform the secure access authentication method provided in the embodiments of this disclosure described above.

[0096] This disclosure also provides a computer program product containing instructions that, when run on an electronic device, cause the electronic device to execute the secure access authentication method provided in the above-described embodiments of this disclosure.

[0097] The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires; a portable computer disk drive; a hard disk drive; a random access memory (RAM); a read-only memory (ROM); an erasable programmable read-only memory (EPROM); a register; a hard disk drive; an optical fiber; a portable compact disc read-only memory (CD-ROM); an optical storage device; a magnetic storage device; or any suitable combination thereof; or any other form of computer-readable storage medium known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may reside in an application-specific integrated circuit (ASIC). In the embodiments of this application, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0098] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A secure access authentication method, characterized in that, Applied to user plane network elements, including: Receive the first data packet from the first terminal; Based on the first data packet, the authentication result of the first terminal is determined; the authentication result of the first terminal is used to indicate whether the first terminal has passed the secure access authentication. An authentication result message is sent to the first terminal, the authentication result message being used to indicate the authentication result of the first terminal.

2. The method according to claim 1, characterized in that, The user plane network element includes a user authentication table; the user authentication table includes authentication result information of multiple terminals; The first data packet includes the identifier of the first terminal; Determining the authentication result of the first terminal based on the first data packet includes: Based on the identifier of the first terminal, determine whether the authentication result information of the first terminal exists in the user authentication table; If the authentication result information of the first terminal is not found in the user authentication table, it is determined that the first terminal has not undergone secure access authentication, and based on the first data packet, the secure access process of the first terminal is executed to determine the authentication result of the first terminal; If the authentication result information of the first terminal exists in the user authentication table, the authentication result of the first terminal is determined based on the user authentication table.

3. The method according to claim 2, characterized in that, The first data packet of the first terminal includes the physical address of the first terminal and the directory number of the client front-end device connected to the first terminal; the step of executing the secure access authentication process of the first terminal based on the first data packet and determining the authentication result of the first terminal includes: Based on the physical address of the first terminal and the catalog number of the customer's front-end device, determine the security access authentication request of the first terminal; Send the secure access authentication request to the authentication server; Receive authentication results from the authentication server within a preset time period.

4. The method according to claim 3, characterized in that, The step of determining the security access authentication request of the first terminal based on the physical address of the first terminal and the directory number of the customer front-end device includes: Generate one-time random numbers based on a pseudo-random number generation algorithm; Encapsulate the current time timestamp, the one-time random number, the directory number, and the physical address to generate the secure access authentication request message; Based on a symmetric encryption algorithm, the encrypted request message generates a secure access authentication request for the first terminal.

5. The method according to claim 3, characterized in that, The method further includes: If the authentication result is the first authentication result, the authentication status of the first terminal in the authentication status table is updated to the first authentication result information; the first authentication result information is used to indicate that the first terminal has passed secure access authentication. If the authentication result is the second authentication result, the authentication status of the first terminal in the authentication status table is updated to the second authentication result information; the second authentication result information is used to indicate that the first terminal has not passed the secure access authentication.

6. The method according to claim 1, characterized in that, The method further includes: If the security access authentication result is the first authentication result, forward the first data packet and subsequent data packets from the first terminal; If the secure access authentication result is the second authentication result, the first data packet and subsequent data packets from the first terminal are discarded.

7. The method according to claim 3, characterized in that, The method further includes: If no secure access authentication result is received from the authentication server within the preset time period, the authentication result will be determined as the second authentication result.

8. A secure access authentication device, characterized in that, The secure access authentication device includes: a communication unit and a processing unit; The communication unit is used to receive the first data packet from the first terminal; The processing unit is configured to determine the authentication result of the first terminal based on the first data packet; the authentication result of the first terminal is used to indicate whether the first terminal has passed the secure access authentication. The communication unit is further configured to send an authentication result message to the first terminal, the authentication result message being used to indicate the authentication result of the first terminal.

9. A secure access authentication device, characterized in that, include: Processor and communication interface; The communication interface is coupled to a processor, which is used to run computer programs or instructions to implement the secure access authentication method as described in any one of claims 1-7.

10. A computer-readable storage medium storing instructions, characterized in that, When the computer executes the instruction, the computer performs the secure access authentication method according to any one of claims 1-7.